fontconfig: security bump to version 2.12.1
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 10 Aug 2016 02:30:16 +0000 (23:30 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Wed, 10 Aug 2016 12:17:28 +0000 (14:17 +0200)
Fixes:
CVE-2016-5384 - possible double free due to insufficiently validated
cache files.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/fontconfig/fontconfig.hash
package/fontconfig/fontconfig.mk

index e4ec1ac177ecca41beeab3361d8af6b1c5f355c7..ad3582557bf3b1da24de6ea14965ef70df93e089 100644 (file)
@@ -1,2 +1,2 @@
-# From http://lists.freedesktop.org/archives/fontconfig/2014-March/005167.html
-sha256 b6b066c7dce3f436fdc0dfbae9d36122b38094f4f53bd8dffd45e195b0540d8d        fontconfig-2.11.1.tar.gz
+# From https://lists.freedesktop.org/archives/fontconfig/2016-August/005794.html
+sha256 b449a3e10c47e1d1c7a6ec6e2016cca73d3bd68fbbd4f0ae5cc6b573f7d6c7f3        fontconfig-2.12.1.tar.bz2
index f3bf0d405df9533e3484a4f8ad1b1972cafe8ad8..93f2a15938598ba9b45fe86b813e95b4116e31a4 100644 (file)
@@ -4,8 +4,9 @@
 #
 ################################################################################
 
-FONTCONFIG_VERSION = 2.11.1
+FONTCONFIG_VERSION = 2.12.1
 FONTCONFIG_SITE = http://fontconfig.org/release
+FONTCONFIG_SOURCE = fontconfig-$(FONTCONFIG_VERSION).tar.bz2
 FONTCONFIG_INSTALL_STAGING = YES
 FONTCONFIG_DEPENDENCIES = freetype expat host-pkgconf
 HOST_FONTCONFIG_DEPENDENCIES = host-freetype host-expat host-pkgconf